@types/co-body
TypeScript definitions for co-body
10
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
types
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@types/qs | AI (dependencies): @types/qs is a DefinitelyTyped type definition package; its use as a dependency in another @types package is expected and benign. | ai | |
| provenance | no-provenance | AI (provenance): DefinitelyTyped packages published via the `types` publisher consistently lack Sigstore provenance; this is a known ecosystem-wide pattern, not a risk indicator. | ai | |
| phantom-deps | phantom-dep:@types/qs | AI (phantom-deps): @types/* packages are loaded by TypeScript convention, not direct imports. This is expected behavior for DefinitelyTyped packages. | ai | |
| phantom-deps | phantom-dep:@types/node | AI (phantom-deps): @types/node is a standard TypeScript ambient type package loaded by convention, not direct import. Expected for DefinitelyTyped packages. | ai |